CVE-2026-107214

Published: Ott 07, 2026 Last Modified: Ott 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.

248

Uncaught Exception

Draft
Common Consequences
Security Scopes Affected:
Availability Confidentiality
Potential Impacts:
Dos: Crash, Exit, Or Restart Read Application Data
Applicable Platforms
Languages: C++, Java, C#
View CWE Details
https://github.com/qax-os/excelize/security/advisories/GHSA-2j4c-ffch-9f23
https://github.com/qax-os/excelize/commit/22f76f9acb94b85b3eb9c4365ab4f750cebbc…
https://github.com/qax-os/excelize/pull/2395
https://github.com/qax-os/excelize/security/advisories/GHSA-2j4c-ffch-9f23